Show filters
6 Total Results
Displaying 1-6 of 6
Sort by:
Attacker Value
Unknown
CVE-2021-34369
Disclosure Date: June 09, 2021 (last updated November 08, 2023)
portlets/contact/ref/refContactDetail.do in Accela Civic Platform through 20.1 allows remote attackers to obtain sensitive information via a modified contactSeqNumber value. NOTE: the vendor states "the information that is being queried is authorized for an authenticated user of that application, so we consider this not applicable.
0
Attacker Value
Unknown
CVE-2021-34370
Disclosure Date: June 09, 2021 (last updated February 22, 2025)
Accela Civic Platform through 20.1 allows ssoAdapter/logoutAction.do successURL XSS. NOTE: the vendor states "there are configurable security flags and we are unable to reproduce them with the available information.
0
Attacker Value
Unknown
CVE-2021-33904
Disclosure Date: June 07, 2021 (last updated February 22, 2025)
In Accela Civic Platform through 21.1, the security/hostSignon.do parameter servProvCode is vulnerable to XSS. NOTE: The vendor states "there are configurable security flags and we are unable to reproduce them with the available information.
0
Attacker Value
Unknown
CVE-2016-5661
Disclosure Date: July 15, 2016 (last updated November 25, 2024)
Accela Civic Platform Citizen Access portal relies on the client to restrict file types for uploads, which allows remote authenticated users to execute arbitrary code via modified _EventArgument and filename parameters.
0
Attacker Value
Unknown
CVE-2016-5660
Disclosure Date: July 15, 2016 (last updated November 25, 2024)
Cross-site scripting (XSS) vulnerability in AttachmentsList.aspx in Accela Civic Platform Citizen Access portal allows remote attackers to inject arbitrary web script or HTML via the iframeid parameter.
0
Attacker Value
Unknown
CVE-2013-4711
Disclosure Date: October 04, 2013 (last updated October 05, 2023)
Cross-site scripting (XSS) vulnerability in Accela BizSearch 3.2 on Linux and Solaris allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
0